zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - September 20, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - September 20, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • International Criminal Court Says It Has Been hacked
  • Trend Micro Releases Fixes For Actively Exploited Flaws
  • ShroudedSnooper's HTTPSnoop Backdoor Targets Middle East Telecom Companies
  • Data broker / initial-access broker / hacktivist group: Exploit user sandocan & Infinity Forum
  • Vulnerabilities: CVE-2023-20900 and CVE-2023-5063
  • Exploits: CVE-2020-8193 and CVE-2020-10199
  • Breaches: Combolist: '12b_splitbo_part_41.txt'

International Criminal Court Says It Has Been hacked

The International Criminal Court (ICC) has disclosed that it detected “anomalous activity affecting its information systems” last week. The institution took immediate action to mitigate the impact of the incident and is working with the Host Country (Netherlands) for additional response and security measures. The Dutch Justice Ministry stated that the country's National Cyber Security Centre was supporting the investigation.

Trend Micro Releases Fixes For Actively Exploited Flaws

Cybersecurity firm Trend Micro has released critical patches and hotfixes for actively exploited security flaws (CVE-2023-41179) in its Apex One and Worry-Free Business Security solutions for Windows. The vulnerability relates to a bundled third-party antivirus uninstaller module. Trend Micro has observed real-world exploitation; while successful attacks require administrative console access, users are urged to apply the patches promptly.

ShroudedSnooper's HTTPSnoop Backdoor Targets Middle East Telecom Companies

Middle East telecom service providers are being targeted by a technique ShroudedSnooper, which relies on a stealthy backdoor called HTTPSnoop. The malware extracts and executes code from incoming malicious requests for specific HTTP(S) URLs. The threat actor also employs a sister implant, PipeSnoop, that accepts arbitrary code execution. ShroudedSnooper is believed to exploit internet-facing servers and impersonates components of Palo Alto Networks’ Cortex XDR Application to avoid detection. Researchers have detected three HTTPSnoop variants so far.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

  • Exploit user sandocan: Auctioning RDP access to an unnamed U.S.-based plastic surgery center
  • Infinity Forum: The underground forum relaunched, with Killmilk reportedly at the head; recruiting moderators and “PR department”.

VULNERABILITIES

  • CVE-2023-20900: A malicious actor that has been granted guest operation privileges in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged guest alias.
  • CVE-2023-5063: The Widget Responsive for Youtube plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'youtube' shortcode in versions up to, and including, 1.6.1 due to insufficient input sanitization and output escaping on user supplied attributes.

EXPLOITS

BREACHES

Tags: DIB, tlp:green